CVE-2026-42174
EUVD-2026-2889009.05.2026, 04:16
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patched in versions 4.9.0 and 5.4.0.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| getkirby | kirby | 𝑥 < 4.9.0 | CNA |
Common Weakness Enumeration